WordPress.org now auto-blocks risky plugin releases with AI-powered security review
Every WordPress.org plugin and theme release is now held in a six-hour cooldown, scored by multiple AI models plus Jetpack Scan, and automatically blocked from distribution if high-risk — a gate introduced after a July 28, 2026 backdoor incident.
The WordPress Official Plugin Repository Team has launched an automated security review for plugin releases. Since June 5, 2026, all releases — including one-click dashboard updates — are held for a six-hour cooldown while multiple AI models and Jetpack Scan cross-check the code changes and produce a consolidated risk score designed to reduce false positives. Releases scoring above the blocking threshold are automatically withheld from the WordPress.org update API. The change follows a July 28, 2026 incident in which a backdoor was committed to a release of a plugin with roughly 20,000 active installations; the backdoor was detected during the cooldown and never delivered to users, and the Plugins Team withheld the release and closed the plugin for downloads 26 minutes after Wordfence notified them. Blocked authors receive an email with the findings and can either publish a corrected release scoring below the threshold — described as usually faster — or appeal to the Plugins Team. The team notes the scores measure risk exposure rather than developer intent and asks authors to report false positives.
- Every WordPress.org plugin and theme release now passes an automated security review and receives a risk score before distribution.
- All releases, including one-click dashboard updates, have been held in a six-hour cooldown since June 5, 2026.
- The review combines multiple AI models with Jetpack Scan to cross-check release changes and reduce false positives.
- Releases exceeding the risk threshold are automatically blocked from the WordPress.org update API until resolved.
- The change followed a July 28, 2026 backdoor committed to a release of a plugin with roughly 20,000 active installations; it was caught during the cooldown and never delivered.
- The Plugins Team withheld the release and closed the plugin for downloads 26 minutes after Wordfence notified them.
- Blocked authors receive an email with the findings and can publish a corrected release scoring below the blocking threshold (usually faster) or appeal to the Plugins Team.
- Risk scores measure risk exposure, not developer intent; the team requests false-positive reports.
Coverage timelineoldest first · each row is one article
- · 6d agoWordPress adds automated security checks to block risky plugin releases
Help Net Security· 55
WordPress.org now automatically security-reviews every plugin release and blocks high-risk updates before distribution to millions of sites.
- · 6d agoWordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites
Cyber Security News· 52
WordPress.org now auto-blocks plugin updates flagged by AI review after a backdoor incident, adding a supply-chain gate for millions of sites.
- · 5d agoWordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review
GBHackers· 58
WordPress.org now runs AI-powered automated security reviews on every plugin release, automatically blocking high-risk updates before distribution to millions of sites.